Stop caching authenticated pages
cache-auth-page
A page carrying session data without no-store can be kept by a CDN or proxy and handed to the next visitor. Mark authenticated responses private.
Why this matters
A page with authentication data (cookies or auth headers) doesn't prevent shared caching. Proxies or CDNs could store and serve your users' private sessions to other visitors.
CDN and edge
Web servers
Frameworks
Cloudflare
- 1 Create a Cache Rule to bypass cache for authenticated paths
- 2 Or set Cache-Control: private at the origin
Does your app still have this?
Scan your domain